Search CVE reports


Toggle filters

11 – 20 of 150 results


CVE-2024-53985

Medium priority
Needs evaluation

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri...

1 affected package

ruby-rails-html-sanitizer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-html-sanitizer Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53989

Medium priority
Needs evaluation

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible...

1 affected package

ruby-rails-html-sanitizer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-html-sanitizer Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-47889

Medium priority

Some fixes available 4 of 7

Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2024-47888

Medium priority

Some fixes available 4 of 7

Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2024-47887

Medium priority

Some fixes available 4 of 7

Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2024-41128

Medium priority

Some fixes available 4 of 7

Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2024-39308

Medium priority
Needs evaluation

RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. Upgrade to 3.1.3 or 2.2.2 (to be released).

1 affected package

ruby-rails-admin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-admin Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-32464

Medium priority
Needs evaluation

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is fixed in...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-28103

Medium priority
Needs evaluation

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in ...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-26144

Medium priority
Needs evaluation

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie...

7 affected packages

rails, ruby-rails-3.2, ruby-actionpack-3.2, ruby-activesupport-3.2, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ruby-rails-3.2 Not in release Not in release Not in release Not in release
ruby-actionpack-3.2 Not in release Not in release Not in release Not in release
ruby-activesupport-3.2 Not in release Not in release Not in release Not in release
ruby-activerecord-3.2 Not in release Not in release Not in release Not in release
ruby-activemodel-3.2 Not in release Not in release Not in release Not in release
rails-4.0 Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages